Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-19034: OS Command Injection in Shibby TomatoCVE-2026-19034
0

Shibby Tomato 1.28.0000 contains a high severity vulnerability in the new_qoslimit_stop function within /tmp/qoslimittc_stop.sh. This vulnerability allows remote attackers with high privileges to perform OS command injection via manipulation of the wan_iface argument. The vulnerability is publicly disclosed and may be exploited. The project has been superseded by FreshTomato.

Join the discussion
CVE-2026-19035: OS Command Injection in Shibby TomatoCVE-2026-19035
0

A command injection vulnerability exists in Shibby Tomato 1.28.0000 within the new_qoslimit_start function of /etc/qoslimit. This flaw allows remote attackers with high privileges to execute arbitrary OS commands by manipulating the new_qoslimit_enable argument. The vulnerability has a high severity score of 7.2 and public exploit code is available. The project has been superseded by FreshTomato.

Join the discussion
CVE-2026-19036: OS Command Injection in Shibby TomatoCVE-2026-19036
0

CVE-2026-19036 is a high-severity OS command injection vulnerability in Shibby Tomato version 1.28.0000. It affects the function sub_40F88C in the file /tmp/ppp/wanoptions, where manipulation of the ppp_custom argument allows remote attackers to execute arbitrary OS commands. The vulnerability is exploitable remotely, and public exploit code has been released. The Shibby Tomato project has been superseded by FreshTomato. No official patch or remediation guidance is currently documented.

Join the discussion
CVE-2026-19035: OS Command Injection in Shibby TomatoCVE-2026-19035
0

CVE-2026-19035 is a high-severity OS command injection vulnerability in Shibby Tomato version 1.28.0000. It affects the function new_qoslimit_start in the /etc/qoslimit file, where manipulation of the new_qoslimit_enable argument can lead to remote OS command injection. The exploit code is publicly available. This project has been superseded by FreshTomato.

Join the discussion
CVE-2026-19034: OS Command Injection in Shibby TomatoCVE-2026-19034
0

A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/shibby/tomato
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses